Skip to main content
Cyber ResilienceIndustry IT8 min readNew

Wire Fraud in Real Estate: How Criminals Steal Closing Money

"A single spoofed email at the wrong moment in a property closing can move a buyer's deposit straight into a criminal's account. Here is how business email compromise works against real estate agencies, and the authentication and verification controls that stop it."

Author

Lior Refael

Published

Aug 8, 2026

Back to Articles

Why closings are the perfect target

A residential or commercial property closing has everything a wire fraud crew wants in one place: a large sum of money, a hard deadline, several parties who have never met in person, and instructions that arrive almost entirely by email. The buyer, the agency, the lawyer or notary and the bank each expect a message from one of the others at some point in the process, and none of them can easily verify a signature on a screen. Business Email Compromise, or BEC, is built for exactly this gap.

The FBI's Internet Crime Complaint Center calls BEC "the 55 billion dollar scam" in its most recent public update, tracking over 305,000 domestic and international incidents and more than 55 billion dollars in exposed losses between October 2013 and December 2023[1]. In 2024 alone, IC3 recorded 21,442 BEC complaints with 2.77 billion dollars in reported losses, and a further 9,359 complaints specifically coded as real estate fraud with 173.6 million dollars lost[2].

Business email compromise vs real estate fraud, IC3 2024

  • Complaints
  • Losses (millions USD)
Business Email Compromise
Real Estate
Show the data
Bar chart comparing 2024 IC3 complaint counts and dollar losses for business email compromise against the real estate fraud category.
CategoryComplaintsLosses (millions USD)
Business Email Compromise21,4422,770.2
Real Estate9,359173.6

Source: FBI Internet Crime Complaint Center (IC3), 2024 Internet Crime Report (2025)

Real estate fraud losses have swung sharply year to year - 396.9 million dollars in 2022, down to 145.2 million in 2023, then back up to 173.6 million in 2024 - which IC3's own data suggests reflects changes in reporting and in how quickly banks intervene, not a shrinking problem[2]. For a small agency handling a handful of closings a month, a single successful redirection can be an existential loss, both financially and to the agency's reputation with the client whose deposit disappeared.

How the fraud actually runs

The pattern is consistent across the cases IC3 and European authorities describe, and it rarely starts with a dramatic hack. It starts with patience.

  1. Reconnaissance. The criminal monitors public listings, agency websites and sometimes a compromised mailbox to learn who is closing on what, and when. Real estate transactions are unusually public - the property, the rough timeline and often the agent's name are all findable with a search.
  2. Access or spoofing. Either the criminal compromises a real mailbox through a phishing email or a reused password, or they register a lookalike domain that differs from the real one by a single character or a swapped letter, and set up matching signatures and email threads.
  3. The pivot. At the point closest to the transfer - usually just before or during the closing window - the criminal sends new wiring instructions, styled to match prior correspondence, often citing a "change of bank" or an "urgent update from the title company."
  4. The transfer. The buyer, the agency's bookkeeper or the party responsible for moving funds wires the deposit or the full purchase amount to the criminal's account, frequently at a bank that acts only as a short-lived intermediary before the money is moved on or converted to cryptocurrency[1].
  5. The window closes fast. Funds are typically moved out of the receiving account within hours, which is why IC3 stresses that a victim's best chance of recovery depends on contacting their bank and filing a complaint within the first 24 to 72 hours[1].

ENISA's 2025 Threat Landscape report, drawn from an analysis of 4,875 recorded incidents across the EU, continues to place social engineering and email-based intrusion among the most consistently reported entry points into small and mid-sized organisations, which is precisely the profile of a local real estate agency[3].

The warning signs a closing team can actually catch

None of these require technical expertise. They require a habit of pausing before a transfer goes out.

  • A last-minute change to bank details. Legitimate title companies, notaries and law firms almost never change their banking information mid-transaction. Any message that does should be treated as fraudulent until proven otherwise.
  • Urgency and pressure language. "This must be sent today," "the seller is threatening to walk," or "please don't call, just confirm by email" are all classic pressure tactics designed to short-circuit verification.
  • A domain that looks right at a glance. Watch for a swapped letter, an extra hyphen, or a different top-level domain from the one your agency and its partners actually use.
  • A reply-to address that does not match the sender. Many BEC messages display a familiar name and address in the header but route replies to a different mailbox entirely.
  • Requests to skip the usual process. Any instruction to bypass a callback, avoid a second signer, or wire funds outside normal banking hours is a signal to stop.

The controls that actually stop it

Email authentication. SPF, DKIM and DMARC, set up correctly and enforced (not just monitored), stop a large share of domain spoofing before it reaches an inbox. NIST's guidance on trustworthy email lays out exactly this stack as the baseline defence against forged sender addresses, and it is a configuration change, not new software, for agencies already on Microsoft 365 or Google Workspace[4].

Out-of-band verification for every payment instruction. Any change to wiring details must be confirmed by phone, using a number pulled from a previous, trusted document rather than one supplied in the suspicious email itself. This single habit defeats the overwhelming majority of BEC attempts, because the criminal cannot fake a phone call to a number they do not control.

A documented two-person rule for transfers. No wire above a set threshold should leave the agency's own systems, or be approved on behalf of a client, without a second person independently confirming the instruction against the original contract.

Multi-factor authentication on every mailbox. Most BEC cases that involve real account compromise, rather than pure spoofing, start with a stolen password on an account without MFA. Enforcing phishing-resistant MFA on every email account closes that door.

A written closing-day protocol shared with clients in advance. Tell buyers, in writing, before the transaction begins, that your agency will never change bank details by email and will never ask for funds to be sent to a new account without a verified phone call. That single sentence, sent early, gives a buyer the confidence to hang up on a fraudster and call your office instead.

What to do in the first hour if it happens anyway

Speed decides whether the money is recoverable. Contact the sending bank immediately and request a wire recall, and ask what documentation they need - policies vary by institution[1]. File a report with the relevant authority - IC3 in the United States, and the equivalent national police cybercrime unit or CERT in Israel, Greece or Spain - as soon as possible, because early reporting is what allows funds to be frozen before they are moved again[2]. Notify every party in the transaction chain in parallel, since the same criminal is very likely targeting the buyer, the seller and the notary with variations of the same message.

Frequently asked questions

Questions we get asked

Sources

Every figure in this article traces back to a named source. Where we quote our own numbers, they come from work we have done with small businesses in Israel and across Europe, and we say so.

  1. Business Email Compromise: The 55 Billion Dollar Scam (opens in a new tab)

    FBI Internet Crime Complaint Center (IC3) · 2024

    Cumulative BEC incident and loss totals from 2013 to 2023, intermediary bank patterns, and the recommendation to contact financial institutions and file a complaint immediately.

  2. 2024 Internet Crime Report (opens in a new tab)

    FBI Internet Crime Complaint Center (IC3) · 2025

    2024 complaint counts and dollar losses for business email compromise and for the real estate crime type, including the three year comparison showing losses in 2022, 2023 and 2024.

  3. ENISA Threat Landscape 2025 (opens in a new tab)

    European Union Agency for Cybersecurity (ENISA) · 2025

    Analysis of 4,875 recorded EU incidents identifying social engineering and email based intrusion as leading entry points into small and mid sized organisations.

  4. SP 800-177 Rev. 1, Trustworthy Email (opens in a new tab)

    National Institute of Standards and Technology (NIST) · 2019

    SPF, DKIM and DMARC as the recommended baseline configuration to prevent domain spoofing and forged sender addresses.

Figures last checked 8 August 2026

Protect your agency's closings before the next transfer goes out

TechSuit sets up email authentication, phishing-resistant MFA and closing-day verification protocols for real estate agencies in Israel, Greece and Spain.